Security Analysis of 103 Protocol of DTU Terminal in Distribution Network Automation
CSTR:
Author:
  • Article
  • | |
  • Metrics
  • |
  • Reference [16]
  • |
  • Related
  • |
  • Cited by
  • | |
  • Comments
    Abstract:

    The IEC 60870-5-103 protocol is an information interface supporting standard applied to relay protection equipment and transmits mainly the information related to relay protection. The message is transmitted in plain text and has poor security for a lack of encryption measures and digital signature mechanism. A communication experiment environment between the master station and the DTU terminal is built to verify that there are hidden dangers in the 103 protocol of Ethernet transmission. A man-in-the-middle attack test is carried out on the system by detecting ARP spoofing. The experimental results show that the 103 protocol of Ethernet transmission faces the risk of man-in-the-middle attack. In order to improve the security of the protocol, we propose a two-way identity authentication mechanism based on an asymmetric cryptographic algorithm and rely on a symmetric encryption mechanism and digital signature technology to ensure the confidentiality and integrity of the transmitted message. Finally, the method is validated through simulation tests.

    Reference
    [1] 张嘉辉. 基于IEC60870-5-103规约的母线弧光保护的研究[硕士学位论文]. 长沙: 湖南大学, 2017.
    [2] 邓素碧, 赵振龙, 陈军, 等. 以太网103规约及其在水电厂自动化系统中应用. 电力自动化设备, 2007, 27(4): 79-82. [doi: 10.3969/j.issn.1006-6047.2007.04.020
    [3] 姬希娜, 浮明军, 杨生苹. 国家电网以太网103规约测试工具的设计与实现. 测控技术, 2016, 35(12): 114-117. [doi: 10.3969/j.issn.1000-8829.2016.12.027
    [4] 张磊, 陈宏君, 吴相楠, 等. 基于扩展103规约的保护装置通信与调试系统设计. 电力系统保护与控制, 2015, 43(21): 126-130
    [5] 李鹏, 范三龙. 基于IEC 60870-5-103规约扩展的牵引供电实时负荷录波设计与实现. 电气技术, 2015, (10): 117-119. [doi: 10.3969/j.issn.1673-3800.2015.10.027
    [6] 韦宇, 莫仕勋. 基于以太网103规约发电机主保护装置的监控系统实现. 电工技术, 2020, (13): 94-96, 100
    [7] 雷林绪, 覃剑, 刘靖. IEC60870-5-103传输规约在行波故障测距装置中的应用. 电网技术, 2007, 31(S2): 252-255
    [8] 余梦泽, 田翠华, 陈柏超, 等. IEC60870-5-103规约在110 kV可控电抗器控制装置中的应用. 继电器, 2008, 36(5): 63-66
    [9] 刘亮亮, 杨启, 沈泽明. 浅谈网络103规约在监控系统中应用优势及存在的问题. 中国电机工程学会电力系统自动化专业委员会2012年学术交流会论文集. 厦门, 中国. 2012. 1-5.
    [10] Sun ZW, Ma YN, Guo QR, et al. Security mechanism for distribution automation using EPON. 2009 IEEE International Conference on Network Infrastructure and Digital Content. Beijing, China. 2009. 581- 585.
    [11] 马春波, 杜以聪, 曾坤. 基于IBC体制的挑战/应答式双向身份认证协议. 计算机工程与设计, 2017, 38(2): 345-349
    [12] 潘维, 黄晓芳. 基于智能合约的身份管理及认证模型. 计算机工程与设计, 2020, 41(4): 915-919
    [13] 周克元. 对一种改进的ElGamal数字签名方案的攻击与改进. 计算机应用与软件, 2019, 36(4): 323-325, 333. [doi: 10.3969/j.issn.1000-386x.2019.04.051
    [14] 邓真, 刘晓洁. HTTPS协议中间人攻击的防御方法. 计算机工程与设计, 2019, 40(4): 901-905
    [15] 裴志江. 一种终端安全防护模型设计方法. 现代电子技术, 2020, 43(9): 75-78
    [16] 何文才, 李娜, 刘培鹤, 等. 一种WSN小数据分发安全方案的研究与设计. 计算机应用与软件, 2018, 35(2): 150-155. [doi: 10.3969/j.issn.1000-386x.2018.02.028
    Related
    Cited by
Get Citation

余鹏,王勇,王相,王敏.配电网自动化DTU终端的103规约的安全性分析.计算机系统应用,2021,30(5):262-268

Copy
Share
Article Metrics
  • Abstract:799
  • PDF: 2377
  • HTML: 2674
  • Cited by: 0
History
  • Received:September 03,2020
  • Revised:September 25,2020
  • Online: May 06,2021
Article QR Code
You are the first991220Visitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063